Vulnerability Database

326,214

Total vulnerabilities in the database

CVE-2020-15394

The REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a crafted request, leading to Remote Code Execution.

  • Published: Sep 25, 2020
  • Updated: Nov 16, 2025
  • CVE: CVE-2020-15394
  • Severity: Critical
  • Exploit:

CVSS v3:

  • Severity: Critical
  • Score: 9.8
  • AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/Au:N/C:P/I:P/A:P

CWEs:

OWASP TOP 10:

Software From Fixed in
zohocorp / manageengine_applications_manager 14.0-build14500 14.0-build14500.x
zohocorp / manageengine_applications_manager 14.0-build14490 14.0-build14490.x
zohocorp / manageengine_applications_manager 14.0-build14480 14.0-build14480.x
zohocorp / manageengine_applications_manager 14.0-build14470 14.0-build14470.x
zohocorp / manageengine_applications_manager 14.0-build14460 14.0-build14460.x
zohocorp / manageengine_applications_manager 14.0-build14450 14.0-build14450.x
zohocorp / manageengine_applications_manager 14.0-build14440 14.0-build14440.x
zohocorp / manageengine_applications_manager 14.0-build14430 14.0-build14430.x
zohocorp / manageengine_applications_manager 14.0-build14401 14.0-build14401.x
zohocorp / manageengine_applications_manager 14.0-build14420 14.0-build14420.x
zohocorp / manageengine_applications_manager 14.0-build14410 14.0-build14410.x
zohocorp / manageengine_applications_manager 14.0-build14361 14.0-build14361.x
zohocorp / manageengine_applications_manager 14.0-build14400 14.0-build14400.x
zohocorp / manageengine_applications_manager 14.0-build14390 14.0-build14390.x
zohocorp / manageengine_applications_manager 14.0-build14380 14.0-build14380.x
zohocorp / manageengine_applications_manager 14.0-build14370 14.0-build14370.x
zohocorp / manageengine_applications_manager 14.0-build14332 14.0-build14332.x
zohocorp / manageengine_applications_manager 14.0-build14360 14.0-build14360.x
zohocorp / manageengine_applications_manager 14.0-build14350 14.0-build14350.x
zohocorp / manageengine_applications_manager 14.0-build14331 14.0-build14331.x
zohocorp / manageengine_applications_manager 14.0-build14340 14.0-build14340.x
zohocorp / manageengine_applications_manager 14.0-build14330 14.0-build14330.x
zohocorp / manageengine_applications_manager 14.0-build14310 14.0-build14310.x
zohocorp / manageengine_applications_manager 14.0-build14300 14.0-build14300.x
zohocorp / manageengine_applications_manager 14.0-build14262 14.0-build14262.x
zohocorp / manageengine_applications_manager 14.0-build14290 14.0-build14290.x
zohocorp / manageengine_applications_manager 14.0-build14280 14.0-build14280.x
zohocorp / manageengine_applications_manager 14.0-build14270 14.0-build14270.x
zohocorp / manageengine_applications_manager 14.0-build14261 14.0-build14261.x
zohocorp / manageengine_applications_manager 14.0-build14260 14.0-build14260.x
zohocorp / manageengine_applications_manager 14.0-build14250 14.0-build14250.x
zohocorp / manageengine_applications_manager 14.0-build14240 14.0-build14240.x
zohocorp / manageengine_applications_manager 14.0-build14230 14.0-build14230.x
zohocorp / manageengine_applications_manager 14.0-build14220 14.0-build14220.x
zohocorp / manageengine_applications_manager 14.0-build14210 14.0-build14210.x
zohocorp / manageengine_applications_manager 14.0-build14200 14.0-build14200.x
zohocorp / manageengine_applications_manager 14.0-build14190 14.0-build14190.x
zohocorp / manageengine_applications_manager 14.0-build14180 14.0-build14180.x
zohocorp / manageengine_applications_manager 14.0-build14170 14.0-build14170.x
zohocorp / manageengine_applications_manager 14.0-build14160 14.0-build14160.x
zohocorp / manageengine_applications_manager 14.0-build14150 14.0-build14150.x
zohocorp / manageengine_applications_manager 14.0-build14140 14.0-build14140.x
zohocorp / manageengine_applications_manager 14.0-build14130 14.0-build14130.x
zohocorp / manageengine_applications_manager 14.0-build14120 14.0-build14120.x
zohocorp / manageengine_applications_manager 14.0-build14110 14.0-build14110.x
zohocorp / manageengine_applications_manager 14.0-build14100 14.0-build14100.x
zohocorp / manageengine_applications_manager 14.0-build14090 14.0-build14090.x
zohocorp / manageengine_applications_manager 14.0-build14080 14.0-build14080.x
zohocorp / manageengine_applications_manager 14.0-build14073 14.0-build14073.x
zohocorp / manageengine_applications_manager 14.0-build14072 14.0-build14072.x
zohocorp / manageengine_applications_manager 14.0-build14071 14.0-build14071.x
zohocorp / manageengine_applications_manager 14.0-build14070 14.0-build14070.x
zohocorp / manageengine_applications_manager 14.0-build14060 14.0-build14060.x
zohocorp / manageengine_applications_manager 14.0-build14050 14.0-build14050.x
zohocorp / manageengine_applications_manager 14.0-build14040 14.0-build14040.x
zohocorp / manageengine_applications_manager 14.0-build14030 14.0-build14030.x
zohocorp / manageengine_applications_manager 14.0-build14020 14.0-build14020.x
zohocorp / manageengine_applications_manager 14.0-build14010 14.0-build14010.x
zohocorp / manageengine_applications_manager 14.0-build14000 14.0-build14000.x
zohocorp / manageengine_applications_manager 14.0-build14510 14.0-build14510.x
zohocorp / manageengine_applications_manager 14.0 14.0.x
zohocorp / manageengine_applications_manager 14.0-build14520 14.0-build14520.x
zohocorp / manageengine_applications_manager 14.0-build14530 14.0-build14530.x
zohocorp / manageengine_applications_manager 14.0-build14540 14.0-build14540.x
zohocorp / manageengine_applications_manager 14.0-build14550 14.0-build14550.x
zohocorp / manageengine_applications_manager 14.0-build14531 14.0-build14531.x
zohocorp / manageengine_applications_manager 14.0-build14560 14.0-build14560.x
zohocorp / manageengine_applications_manager 14.0-build14570 14.0-build14570.x
zohocorp / manageengine_applications_manager 14.0-build14580 14.0-build14580.x
zohocorp / manageengine_applications_manager 14.0-build14590 14.0-build14590.x
zohocorp / manageengine_applications_manager 14.0-build14600 14.0-build14600.x
zohocorp / manageengine_applications_manager 14.0-build14532 14.0-build14532.x
zohocorp / manageengine_applications_manager 14.0-build14610 14.0-build14610.x
zohocorp / manageengine_applications_manager 14.0-build14620 14.0-build14620.x
zohocorp / manageengine_applications_manager 14.0-build14630 14.0-build14630.x
zohocorp / manageengine_applications_manager 14.0-build14533 14.0-build14533.x
zohocorp / manageengine_applications_manager 14.0-build14660 14.0-build14660.x
zohocorp / manageengine_applications_manager 14.0-build14670 14.0-build14670.x
zohocorp / manageengine_applications_manager 14.0-build14681 14.0-build14681.x
zohocorp / manageengine_applications_manager 14.0-build14682 14.0-build14682.x
zohocorp / manageengine_applications_manager 14.0-build14690 14.0-build14690.x
zohocorp / manageengine_applications_manager 14.0-build14700 14.0-build14700.x
zohocorp / manageengine_applications_manager 14.0-build14683 14.0-build14683.x
zohocorp / manageengine_applications_manager 14.0-build14684 14.0-build14684.x
zohocorp / manageengine_applications_manager 14.0-build14685 14.0-build14685.x
zohocorp / manageengine_applications_manager 14.0-build14710 14.0-build14710.x
zohocorp / manageengine_applications_manager 14.0-build14720 14.0-build14720.x
zohocorp / manageengine_applications_manager - 14.0
zohocorp / manageengine_applications_manager 14.0-build14730 14.0-build14730.x

Frequently Asked Questions

A security vulnerability is a weakness in software, hardware, or configuration that can be exploited to compromise confidentiality, integrity, or availability. Many vulnerabilities are tracked as CVEs (Common Vulnerabilities and Exposures), which provide a standardized identifier so teams can coordinate patching, mitigation, and risk assessment across tools and vendors.

CVSS (Common Vulnerability Scoring System) estimates technical severity, but it doesn't automatically equal business risk. Prioritize using context like internet exposure, affected asset criticality, known exploitation (proof-of-concept or in-the-wild), and whether compensating controls exist. A "Medium" CVSS on an exposed, production system can be more urgent than a "Critical" on an isolated, non-production host.

A vulnerability is the underlying weakness. An exploit is the method or code used to take advantage of it. A zero-day is a vulnerability that is unknown to the vendor or has no publicly available fix when attackers begin using it. In practice, risk increases sharply when exploitation becomes reliable or widespread.

Recurring findings usually come from incomplete Asset Discovery, inconsistent patch management, inherited images, and configuration drift. In modern environments, you also need to watch the software supply chain: dependencies, containers, build pipelines, and third-party services can reintroduce the same weakness even after you patch a single host. Unknown or unmanaged assets (often called Shadow IT) are a common reason the same issues resurface.

Use a simple, repeatable triage model: focus first on externally exposed assets, high-value systems (identity, VPN, email, production), vulnerabilities with known exploits, and issues that enable remote code execution or privilege escalation. Then enforce patch SLAs and track progress using consistent metrics so remediation is steady, not reactive.

SynScan combines attack surface monitoring and continuous security auditing to keep your inventory current, flag high-impact vulnerabilities early, and help you turn raw findings into a practical remediation plan.